port_8443_scanning_internal

Explanation

This NDM was created by the Netography Threat Research team to detect unauthorized scanning activities on port 8443 inside the network.

What to Look For

When reviewing the results of this NDM event, look for any Source IPs that are not authorized for scanning activities on port 8443. These IPs should be investigated immediately to determine if there is any malicious intent behind the scanning activity. Remediation steps should be taken to block or restrict access to these IPs to prevent further scanning activities on the network.

Related MITRE ATT&CK Categories

Network Service Discovery, Technique T1046 - Enterprise

Active Scanning, Technique T1595 - Enterprise